What are the key advantages of Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base?
Central management – Managed centrally from an on-premises Kaspersky Security Center.
Server scope – Licences SCADA, historian and other industrial server nodes.
EDR included – Telemetry, IoC scans and cross-endpoint response actions.
Legacy compatibility – Runs on old Windows Server builds still in production.
PLC integrity – Checks Siemens and Schneider Electric controller projects for changes.
Important note – Management console and network agent are not included.
Industrial endpoint protection – Real-time file protection for ICS and SCADA server nodes.
Endpoint detection and response – IoC scanning, telemetry collection and attack spread path analysis.
Response actions – Quarantine files, terminate processes, block execution, isolate the node.
Local activity control – Application launch control, device control and Wi-Fi control.
PLC project integrity check – Detects changes in Siemens, Schneider Electric and CODESYS projects.
Important – Kaspersky Security Center and Network Agent are not included.
Kaspersky Industrial CyberSecurity for Nodes, commonly shortened to KICS for Nodes, is industrial-grade endpoint protection with detection and response for the server-class machines in an automation network: SCADA servers, historian servers, gateways and OT application servers. This variant is managed centrally from an on-premises Kaspersky Security Center rather than from a cloud console, so policies, events and telemetry stay inside the plant network.
New licence – Base is a new licence, not a renewal or cross-grade.
On-premises console – Policies and events stay inside the plant network.
Legacy Windows support – Protects old Windows Server builds still running production lines.
Low process impact – Tunable resource use and non-intrusive default settings.
OVAL compliance audit – Vulnerability and configuration checks against published OVAL definitions.
Automation vendor compatibility – Over 200 compatibility certificates with automation vendor solutions.
This is an OT product, so the deciding factor is not headcount but whether you run an automation network with server-class nodes and already operate a Kaspersky Security Center. The table shows how often each factor applies to a company of that size.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Kaspersky Security Center already operated | Rare | Partial | ✓ |
| This product fits | Limited | ✓ | ✓ |
The Information Security Act (ISG) has been in force since 1 January 2024, and the supplementary provisions on the reporting duty took effect on 1 April 2025; they apply to operators of critical infrastructure such as energy suppliers, water utilities, transport operators and hospitals, not to every industrial company. Affected operators must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which in practice means being able to say within one day what was hit and how far it spread. The EDR component supports exactly that part: it collects endpoint telemetry, reconstructs the attack spread path and timestamps the detection chain, so the first report is based on recorded events rather than on an operator recollection. What it does not cover is the reporting act itself, the OT network side of the picture, which requires KICS for Networks, and the organisational duty to decide whether an incident is significant enough to be reportable. This description is not legal advice; whether the reporting obligation applies to your organisation should be clarified with a qualified specialist.
No security product creates NIS 2 compliance, because the Directive addresses the organisation and its management, not a piece of software. The NIS 2 Directive requires measures in categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, basic cyber hygiene and training, cryptography, access control, and multi-factor authentication. This product contributes to two of those categories in a concrete way: incident handling, through detection, telemetry and response actions on server nodes, and vulnerability handling, through the OVAL-based audit that checks node configuration and known vulnerabilities. It contributes nothing to business continuity and backup, cryptography, multi-factor authentication, staff training or supply chain governance, all of which need separate products or processes. Treat it as evidence for the endpoint layer of the incident-handling requirement, not as coverage of the requirement set.
Two official measures concerning the vendor are currently in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products; the BSI states that it made no assessment of Kaspersky products outside that antivirus portfolio, and the warning was still in force and being contested by Kaspersky in 2026. In the United States, the Department of Commerce issued a final determination on 20 June 2024 that barred new agreements with US persons from 20 July 2024 and, from 29 September 2024, prohibited signature and codebase updates as well as operation of the Kaspersky Security Network on US systems. Kaspersky's own position is that the German warning is not justified and was not based on an objective technical analysis of the risks of using its software. Verified independent facts are unaffected by these measures: threat data submitted by European users is processed in two data centres in Zurich, the information security management system covering that infrastructure is certified to ISO/IEC 27001:2022, and the vendor holds over 200 compatibility certificates with automation vendors. Practically, this matters most if you supply the German or US public sector, if your group has US entities, or if customer supply chain requirements exclude vendors subject to a national authority warning; for a purely Swiss industrial operator with no such exposure it is a documentation point rather than a blocker.
Yes, for the endpoint and OT-node sections, and not at all for several others. It answers questions on malware protection of production servers, application allowlisting, removable-media and device control, host firewall management, file integrity and registry monitoring, endpoint detection and response coverage, incident response actions available to the security team, and vulnerability and configuration auditing against OVAL definitions. It does not answer questions on backup and restore, disaster recovery testing, disk or file encryption, multi-factor authentication, third-party patch management, mobile device management, email security, or OT network traffic monitoring, and it does not produce an attestation about the vendor's country of origin, which is increasingly its own questionnaire item. The cheapest way to close the OT-side gaps is usually to stay in the same family and add KICS for Networks for the network layer rather than introducing a second vendor with a second console; backup, encryption and patching, however, have no counterpart in this family and must be sourced separately.
The single decisive difference is investigation: the EDR variant turns the agent into an endpoint sensor that stores telemetry, scans for indicators of compromise and reconstructs how an incident spread, while the plain variant blocks and reports but leaves you without that history afterwards. Both variants protect the same server nodes with the same protection and control components, and both are managed from the same console, so this is not a protection-strength decision. Choose the EDR variant if you have to explain an incident after the fact, whether to an authority, an insurer or a customer auditor. Choose the plain variant if malware blocking on the node is all you need and no one will ask you to reconstruct a timeline. Note that the EDR capability is delivered inside the same agent and needs no additional appliance on the plant floor.
| Capability | Server Enterprise | Server EDR Enterprise |
|---|---|---|
| Real-time file protection | ✓ | ✓ |
| Application and device control | ✓ | ✓ |
| PLC project integrity check | ✓ | ✓ |
| Telemetry and IoC scanning | ✕ | ✓ |
| Attack spread path analysis | ✕ | ✓ |
| Cross-endpoint response actions | ✕ | ✓ |
| Available to US persons | ✕ | ✕ |
There is a hard regional limitation: since 29 September 2024 the vendor may not supply signature or codebase updates to US persons, and the Kaspersky Security Network may not operate on US systems, so this product is not a viable choice for a plant in the United States or for a group whose OT security is administered from there. Coverage is also narrower than the family name suggests in three ways: it licenses server-class nodes only, so HMIs and engineering workstations need the Workstation variant; it is a Windows application, so industrial Linux nodes need the separate KICS for Linux Nodes product; and it secures the node, not the wire, so OT network traffic analysis requires KICS for Networks. The most common follow-up purchase is the management infrastructure itself, because Kaspersky Security Center and its Network Agent are deployed separately and the Network Agent is not part of this distribution kit. Finally, there is no backup, no disk encryption and no third-party patch management in this product, which is where buyers coming from a general IT endpoint suite are most often caught out.
Yes, and this is one of the main reasons the product exists. Nodes running as far back as Windows XP SP2 and Windows Server 2003 can be managed through Kaspersky Security Center, although those particular systems require an older Network Agent build rather than the current one.
The vendor names Siemens SIMATIC S7-300, S7-400, S7-400H, S7-1200 and S7-1500, SIPROTEC 4, Schneider Electric Modicon M340 and M580, CODESYS V3 devices, and Fastwel CPM723-01. If your controllers are not on that list, the rest of the protection still applies but the project integrity check will not.
Suspicious and malicious files that products submit to the Kaspersky Security Network from European users are processed in two data centres in Zurich, Switzerland. The information security management system covering that infrastructure is certified to ISO/IEC 27001:2022, which is a point worth recording when a customer audit asks where security telemetry leaves the country.